PRIVACY POLICY
CONTROLLER AND CONTACT
For operation of the Website, general enquiries and company-contracted services, the controller is VICO FLOÉ, S.L., NIF B24671220, Carrer d’Alemanya 43, 2-2, 08201 Sabadell, Barcelona, Spain. For original-art and artist-commission transactions contracted and invoiced by the author, the controller is Wiktoria Maria Florek Maceluch, self-employed professional artist, NIF 10242511J, at the same professional address. Each acts as controller for its own processing and will identify itself in the relevant offer or invoice. Shared privacy contact: hello@wiktoriaflorek.com. No data protection officer has been designated unless the Website is later updated to state otherwise.
DATA WE PROCESS
Identity and contact data: name, title, company, postal/billing/delivery address, email, telephone, WhatsApp identifier and communication preferences.
Enquiry, relationship and project data: messages, preferences, artwork interests, site/project information, appointment history, offers, approvals and correspondence.
Transaction and compliance data: order, invoice, tax/VAT, payment status, refunds, shipping, insurance, customs, identity and sanctions-check information. We do not store full card credentials.
Website and device data: IP address, device/browser, logs, consent choices, page interactions, referring URLs and cookie/analytics identifiers where permitted.
Marketing data: collector-list subscription, consent record, campaign interaction and inferred interests based on direct engagement where lawful.
Images and archive data: artwork installation or event images, authentication/provenance records, and collector attribution only where agreed or otherwise lawful.
PURPOSE, LEGAL BASIS AND RETENTION
We process data only where a legal basis applies:
Enquiries and pre-contract steps — to respond and prepare offers at the person’s request (GDPR Art. 6(1)(b)); business-contact communications may also rely on legitimate interests (Art. 6(1)(f)). Retention: ordinarily up to 24 months after the last meaningful contact, unless a relationship or legal issue continues.
Orders, commissions, delivery, insurance, aftercare and customer service — contract performance (Art. 6(1)(b)). Retention: for the relationship and then for applicable limitation periods.
Invoices, accounting, tax, customs, sanctions and legal compliance — legal obligation (Art. 6(1)(c)). Retention: statutory periods, commonly at least six years for commercial documentation and longer where tax or other law requires.
Fraud prevention, security, dispute handling, rights protection and basic business administration — legitimate interests (Art. 6(1)(f)), balanced against individual rights. Retention: as necessary for the risk or claim and applicable limitation periods.
Email collector list and non-customer electronic marketing — consent (Art. 6(1)(a) GDPR and LSSI-CE). Existing-customer marketing may rely on the legally permitted similar-products exception, always with a simple opt-out. Retention: until consent is withdrawn/opt-out, followed by a minimal suppression record.
Non-essential cookies, analytics and similar storage/access — consent (Art. 6(1)(a) and LSSI-CE). Retention: as specified in the live cookie settings and provider controls.
Public identification of a private collector, testimonial, portrait or identifiable event participant — consent or a separate release where required. Retention: for the stated use or until valid withdrawal, without affecting prior lawful use.
REQUIRED AND OPTIONAL DATA
Fields marked required, and information needed to quote, contract, invoice, screen a high-value transaction, ship or insure a work, are necessary for those purposes. Without them, we may be unable to proceed. Marketing consent and non-essential cookies are optional and refusal does not prevent ordinary access or purchase discussions.
RECIPIENTS AND SERVICE PROVIDERS
Data may be disclosed only as necessary to processors and independent recipients. Current material providers include Flodesk for the collector newsletter and email marketing; GoHighLevel/HighLevel (including relevant LeadConnector infrastructure) for customer-relationship management and communications; BBVA and relevant card/payment-network infrastructure for banking and secure card payments; NitroPack and its delivery infrastructure for Website optimisation; the Website hosting, maintenance, email, contact-form and cookie-consent providers; and professional advisers, insurers, couriers, fine-art handlers, customs agents, installers, warehouses, fraud/sanctions screening providers, competent authorities, and a purchaser or adviser in a genuine corporate transaction subject to safeguards.
WhatsApp enquiries involve Meta/WhatsApp as an independent provider under its own terms and privacy information. Do not send payment-card numbers, passports or other unnecessary sensitive data through WhatsApp. Where a named vendor is material to transparency—particularly newsletter, analytics, payment and embedded-media vendors—it must also be identified in the live cookie settings or this policy after the implementation audit.
INTERNATIONAL TRANSFERS
Some providers may process data outside the European Economic Area. Where required, we use an adequacy decision (including an applicable EU–US Data Privacy Framework certification), the European Commission’s Standard Contractual Clauses with supplementary measures, or another lawful safeguard. Information or copies of relevant safeguards may be requested, subject to lawful redactions. We do not rely on the former EU–US Privacy Shield.
RIGHTS
Depending on the circumstances, individuals may request access, rectification, erasure, restriction, portability, or object to processing; withdraw consent at any time; and object at any time to direct marketing. Withdrawal does not affect earlier lawful processing. Requests may be sent to hello@wiktoriaflorek.com. We may request proportionate identity verification and will respond within the statutory period.
Individuals may complain to the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to another competent supervisory authority, particularly in their EU/EEA country of habitual residence or work.
AUTOMATED DECISIONS, CHILDREN AND SECURITY
We do not make decisions producing legal or similarly significant effects solely by automated means unless a specific notice says otherwise. The Website and art acquisition services are not directed to children. We use proportionate technical and organisational measures, but no internet transmission is completely secure. Users should avoid sending unnecessary sensitive information through open channels.
THIRD-PARTY SITES AND POLICY CHANGES
Third-party sites and platforms have their own privacy rules. We may update this Policy to reflect legal, technical or business changes. Material changes will be highlighted where appropriate, and the effective date will be updated.